Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

Missing Authorization
CVE Not available
CVSS High (8.8)
Publicly Published February 25, 2019
Last Updated January 22, 2024
Description

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.

References

134 affected software package

Software Type Plugin
Software Slug ultimeter (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.9.3
Patched Version
  • 1.9.3
Software Type Plugin
Software Slug past-events-extension (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.1
Patched Version
Software Type Plugin
Software Slug geo-request (view on wordpress.org)
Patched? No
Affected Version
  • <= 0.1.9
Patched Version
Software Type Plugin
Software Slug section-slider (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug krsp-frontend-file-upload (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0
Patched Version
Software Type Plugin
Software Slug resermy (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug premmerce-woocommerce-wholesale-pricing (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.4
Patched Version
  • 1.1.4
Software Type Plugin
Software Slug any-popup (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0
Patched Version
Software Type Plugin
Software Slug enhanced-catalog-images-for-woocommerce (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.1
Patched Version
Software Type Plugin
Software Slug error-log-monitor (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.6.5
Patched Version
  • 1.6.5
Software Type Plugin
Software Slug featured-image-toolkit (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.3
Patched Version
Software Type Plugin
Software Slug wp-advance-comment (view on wordpress.org)
Patched? No
Affected Version
  • <= 0.3
Patched Version
Software Type Plugin
Software Slug wp-private-media (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.1
Patched Version
Software Type Plugin
Software Slug devices (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Theme
Software Slug consultpress-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.3
Patched Version
Software Type Plugin
Software Slug animate-everything (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.2
Patched Version
Software Type Plugin
Software Slug woorocks-magic-content (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.17
Patched Version
Software Type Plugin
Software Slug popup-maker (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.8.3
Patched Version
  • 1.8.3
Software Type Plugin
Software Slug addons-for-elementor (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.6
Patched Version
  • 2.6
Software Type Plugin
Software Slug demomentsomtres-address (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.1
Patched Version
Software Type Plugin
Software Slug web-disrupt-funnelmentals (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.9
Patched Version
  • 1.2.9
Software Type Plugin
Software Slug better-robots-txt (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.6
Patched Version
  • 1.2.6
Software Type Plugin
Software Slug gfirem-fields (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.7
Patched Version
Software Type Plugin
Software Slug giveasap (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.18.0
Patched Version
  • 2.18.0
Software Type Plugin
Software Slug edd-tab-manager (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.1
Patched Version
  • 1.3.1
Software Type Plugin
Software Slug gfirem-action-after (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.6
Patched Version
Software Type Plugin
Software Slug a-staff (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.2
Patched Version
Software Type Plugin
Software Slug wgauge (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug buddyforms (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.3.2
Patched Version
  • 2.3.2
Software Type Plugin
Software Slug social-gallery-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 3.1
Patched Version
Software Type Plugin
Software Slug premmerce-woocommerce-wishlist (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.3
Patched Version
  • 1.1.3
Software Type Plugin
Software Slug starfish-reviews (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.1
Patched Version
  • 2.0.1
Software Type Plugin
Software Slug advanced-classifieds-and-directory-pro (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.6.3
Patched Version
  • 1.6.3
Software Type Plugin
Software Slug next-order-coupon-woocommerce (view on wordpress.org)
Patched? No
Affected Version
  • <= 0.4.0
Patched Version
Software Type Plugin
Software Slug addendio (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.2
Patched Version
Software Type Plugin
Software Slug price-bands-for-woocommerce (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.4
Patched Version
Software Type Plugin
Software Slug perelandra-sermons (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.0
Patched Version
Software Type Plugin
Software Slug wp-munich-blocks (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.7.3
Patched Version
  • 0.7.3
Software Type Plugin
Software Slug go-fetch-jobs-jobengine (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0
Patched Version
Software Type Plugin
Software Slug gfirem-advance-search (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.2
Patched Version
Software Type Theme
Software Slug speculor (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.0
Patched Version
Software Type Plugin
Software Slug remove-wp-update-nags (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.0
Patched Version
  • 1.4.0
Software Type Plugin
Software Slug content-collector (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.1
Patched Version
Software Type Plugin
Software Slug foogallery (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.6.17
Patched Version
  • 1.6.17
Software Type Plugin
Software Slug stop-user-enumeration (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.20
Patched Version
  • 1.3.20
Software Type Plugin
Software Slug ultimate-social-media-plus (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.0.4
Patched Version
  • 3.0.4
Software Type Plugin
Software Slug tinymce-annotate (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.2
Patched Version
Software Type Plugin
Software Slug woo-admin-product-notes (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug run-time-image-resizing (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1
Patched Version
Software Type Plugin
Software Slug add-pinterest-conversion-tags (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.2
Patched Version
  • 1.0.2
Software Type Plugin
Software Slug one-page-blocks (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug page-studio-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.6
Patched Version
Software Type Theme
Software Slug shuban (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.2
Patched Version
Software Type Plugin
Software Slug demomentsomtres-grid-archive (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.1
Patched Version
Software Type Plugin
Software Slug random-sorting-order-for-woocommerce (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0
Patched Version
Software Type Plugin
Software Slug inbound-brew (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.9.4
Patched Version
Software Type Plugin
Software Slug wp-photo-effects (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.3
Patched Version
  • 1.2.3
Software Type Plugin
Software Slug turbo-widgets (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.0.0
Patched Version
Software Type Plugin
Software Slug press-elements (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.7.2
Patched Version
Software Type Plugin
Software Slug buddyforms-easypin (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.1
Patched Version
Software Type Plugin
Software Slug sexy-author-bio (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.5.5
Patched Version
Software Type Plugin
Software Slug rw-divi-unite-gallery (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0
Patched Version
Software Type Plugin
Software Slug revolution-for-elementor (view on wordpress.org)
Patched? No
Affected Version
  • <= 0.0.19
Patched Version
Software Type Plugin
Software Slug quick-orders-for-woocommerce (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.2
Patched Version
Software Type Plugin
Software Slug feedback-suite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.5
Patched Version
Software Type Plugin
Software Slug content-aware-sidebars (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.8.1
Patched Version
  • 3.8.1
Software Type Theme
Software Slug bani (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.7
Patched Version
Software Type Plugin
Software Slug fast-wp (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.3
Patched Version
Software Type Plugin
Software Slug import-social-statistics (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.2
Patched Version
Software Type Plugin
Software Slug wc4bp (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.2.6.1
Patched Version
  • 3.2.6.1
Software Type Plugin
Software Slug review-engine (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.41
Patched Version
Software Type Plugin
Software Slug wp-seo-keyword-optimizer (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.9.8
Patched Version
  • 2.1.9.8
Software Type Plugin
Software Slug ultimate-widgets-light (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.5.9.4
Patched Version
Software Type Plugin
Software Slug insert-or-embed-articulate-content-into-wordpress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 4.2997
Patched Version
  • 4.2997
Software Type Plugin
Software Slug nitek-carousel-cool-transitions (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.0
Patched Version
Software Type Plugin
Software Slug wp-security-audit-log (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.3.1.2
Patched Version
  • 3.3.1.2
Software Type Plugin
Software Slug reach-us-contact-form (view on wordpress.org)
Patched? No
Affected Version
  • <= 5.0
Patched Version
Software Type Plugin
Software Slug widgets-for-siteorigin (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.3
Patched Version
  • 1.4.3
Software Type Plugin
Software Slug nexus (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.0
Patched Version
Software Type Plugin
Software Slug wpworx-faq (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.0.0
Patched Version
Software Type Theme
Software Slug brand (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.9.1
Patched Version
Software Type Plugin
Software Slug premmerce-woocommerce-variation-swatches (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1
Patched Version
  • 1.1
Software Type Plugin
Software Slug sprout-clients (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.1
Patched Version
  • 3.2
Software Type Plugin
Software Slug kanzu-support-desk (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.4.7
Patched Version
Software Type Plugin
Software Slug expire-tags (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1
Patched Version
Software Type Plugin
Software Slug reviewpress (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.5
Patched Version
Software Type Plugin
Software Slug mobile-menu (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.7.3
Patched Version
  • 2.7.3
Software Type Plugin
Software Slug cp-simple-newsletter (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1
Patched Version
Software Type Plugin
Software Slug demomentsomtres-categories (view on wordpress.org)
Patched? No
Affected Version
  • <= 201704251008
Patched Version
Software Type Plugin
Software Slug wp-relevant-ads (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug giveaways-for-woocommerce (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug demomentsomtres-media-tools-auto (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.0
Patched Version
Software Type Plugin
Software Slug drop-shadow-boxes (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.7.2
Patched Version
  • 1.7.2
Software Type Plugin
Software Slug 404-to-301 (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.0.2
Patched Version
  • 3.0.2
Software Type Plugin
Software Slug before-and-after-product-images-for-woocommerce (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.3
Patched Version
Software Type Plugin
Software Slug customer-chat-facebook (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.1
Patched Version
Software Type Plugin
Software Slug delete-duplicate-posts (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 4.1.9.5
Patched Version
  • 4.1.9.5
Software Type Plugin
Software Slug post-snippets (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.0.6
Patched Version
  • 3.0.6
Software Type Plugin
Software Slug helpie-faq (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.7.2
Patched Version
  • 0.7.2
Software Type Plugin
Software Slug livemesh-siteorigin-widgets (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.5.2
Patched Version
  • 2.5.2
Software Type Plugin
Software Slug gravity-forms-sticky-list (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.5.2
Patched Version
Software Type Plugin
Software Slug wp-fail2ban (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 4.0.5
Patched Version
  • 4.0.5
Software Type Plugin
Software Slug final-tiles-grid-gallery-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.3.57
Patched Version
  • 3.3.57
Software Type Plugin
Software Slug foobox-image-lightbox (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.6.4
Patched Version
  • 2.6.4
Software Type Plugin
Software Slug contact-form-7-multi-step-module (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.0.9
Patched Version
  • 3.0.9
Software Type Plugin
Software Slug demomentsomtres-classify-on-publish (view on wordpress.org)
Patched? No
Affected Version
  • <= 201703020805
Patched Version
Software Type Plugin
Software Slug wp-buddha-free-adwords (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Theme
Software Slug purus (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.2
Patched Version
Software Type Plugin
Software Slug rm-mailchimp-manager (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.2
Patched Version
Software Type Plugin
Software Slug automatic-post-categories (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0
Patched Version
Software Type Plugin
Software Slug global-income-stats-from-freemius (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug cryptocurrency (view on wordpress.org)
Patched? No
Affected Version
  • <= 0.0.17
Patched Version
Software Type Plugin
Software Slug woorocks-magic-content-for-siteorigins-pagebuilder (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.1
Patched Version
Software Type Plugin
Software Slug master-blocks (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.4
Patched Version
Software Type Plugin
Software Slug widgets-on-pages-and-posts (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.4.0
Patched Version
Software Type Plugin
Software Slug sheetpress (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1
Patched Version
Software Type Plugin
Software Slug typea-ftc-disclosure (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.0
Patched Version
Software Type Plugin
Software Slug wp-pro-counter (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1
Patched Version
Software Type Plugin
Software Slug nugget-by-ingot (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.0
Patched Version
Software Type Plugin
Software Slug wp-to-twitter (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.3.0
Patched Version
  • 3.3.0
Software Type Plugin
Software Slug best-woocommerce-feed (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.2.3.1
Patched Version
  • 2.2.3.1
Software Type Plugin
Software Slug custom-registration-and-login-forms-with-new-recaptcha (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1
Patched Version
Software Type Plugin
Software Slug freemage (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0
Patched Version
Software Type Plugin
Software Slug co2ok-for-woocommerce (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.9.21
Patched Version
  • 1.0.9.22
Software Type Plugin
Software Slug snazzyadmin-wp-admin-theme (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.2
Patched Version
Software Type Plugin
Software Slug admin-notices-for-team (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.4
Patched Version
  • 1.0.4
Software Type Plugin
Software Slug edd-courses (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.1.1
Patched Version
  • 0.1.1
Software Type Plugin
Software Slug wp-affiliate-disclosure (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.4
Patched Version
  • 1.1.4
Software Type Plugin
Software Slug nextgen-gallery (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.1.7
Patched Version
  • 3.1.7
Software Type Plugin
Software Slug multilist-subscribe-for-sendy (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.6.1
Patched Version
Software Type Plugin
Software Slug easy-code-snippets (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.1
Patched Version
  • 1.0.1
Software Type Plugin
Software Slug premmerce-woocommerce-product-filter (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.2
Patched Version
  • 3.2
Software Type Plugin
Software Slug easy-watermark (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.7.1
Patched Version
  • 0.7.1
Software Type Plugin
Software Slug cp-image-gallery (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.1
Patched Version
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.